CVE-2023-45857
Vulnerability Summary
Timeline
Description
An issue discovered in Axios 1.5.1 inadvertently reveals the confidential XSRF-TOKEN stored in cookies by including it in the HTTP header X-XSRF-TOKEN for every request made to any host allowing attackers to view sensitive information.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.56%• Percentile: 45%
Techniques & Countermeasures
- CWE-352•Cross-Site Request Forgery (CSRF)
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Affected Systems
- chainguard•arangodb-3.11
< 3.11.14.5-r13
- chainguard•gitlab-rails-ce-18.1
all
- chainguard•gitlab-rails-ce-18.10
all
- chainguard•gitlab-rails-ce-18.11
all
- chainguard•gitlab-rails-ce-18.5
all
- chainguard•gitlab-rails-ce-18.6
all
- chainguard•gitlab-rails-ce-18.7
all
- chainguard•gitlab-rails-ce-18.8
all
- chainguard•gitlab-rails-ce-18.9
all
- chainguard•gitlab-rails-ce-19.0
all
- chainguard•gitlab-rails-ce-19.1
all | < 19.1.7-r6
- chainguard•gitlab-rails-ce-19.2
all | < 19.2.5-r2
- chainguard•gitlab-rails-ce-19.3
< 19.3.1-r6
- chainguard•gitlab-rails-ce-fips-18.1
all
- chainguard•gitlab-rails-ce-fips-18.10
all
- chainguard•gitlab-rails-ce-fips-18.11
all
- chainguard•gitlab-rails-ce-fips-18.5
all
- chainguard•gitlab-rails-ce-fips-18.6
all
- chainguard•gitlab-rails-ce-fips-18.7
all
- chainguard•gitlab-rails-ce-fips-18.8
all
- chainguard•gitlab-rails-ce-fips-18.9
all
- chainguard•gitlab-rails-ce-fips-19.0
all
- chainguard•gitlab-rails-ce-fips-19.1
all | < 19.1.7-r7
- chainguard•gitlab-rails-ce-fips-19.2
all | < 19.2.5-r2
- chainguard•gitlab-rails-ce-fips-19.3
< 19.3.1-r3
- chainguard•opensearch-dashboards-2
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-alerting-dashboards-plugin
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-anomaly-detection-dashboards-plugin
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-config
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-maps
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-notifications
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-observability
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-query-workbench
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-reporting
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-search-relevance
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-dashboards-visualizations
< 2.11.1-r2
- chainguard•opensearch-dashboards-2-fips
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-alerting-dashboards-plugin
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-anomaly-detection-dashboards-plugin
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-config
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-maps
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-notifications
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-observability
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-query-workbench
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-reporting
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-search-relevance
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-dashboards-visualizations
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-index-management-dashboards-plugin
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-ml-commons-dashboards
< 2.13.0-r0
- chainguard•opensearch-dashboards-2-fips-security-analytics-dashboards-plugin
< 2.13.0-r0
Showing first 50 affected entries in server-rendered view.
References (16)
- https://github.com/axios/axios/issues/6006
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://nvd.nist.gov/vuln/detail/CVE-2023-45857
- https://github.com/axios/axios/issues/6022
- https://github.com/axios/axios/pull/6028
- https://github.com/axios/axios/pull/6091
- https://github.com/axios/axios/commit/2755df562b9c194fba6d8b609a383443f6a6e967
- https://github.com/axios/axios/commit/96ee232bd3ee4de2e657333d4d2191cd389e14d0
- https://github.com/axios/axios
- https://github.com/axios/axios/releases/tag/v0.28.0
- https://github.com/axios/axios/releases/tag/v1.6.0
- https://security.netapp.com/advisory/ntap-20240621-0006
- https://security.snyk.io/vuln/SNYK-JS-AXIOS-6032459
- https://security-tracker.debian.org/tracker/CVE-2023-45857
- https://ubuntu.com/security/CVE-2023-45857
- https://www.cve.org/CVERecord?id=CVE-2023-45857